Use the CLI commands in this procedure to enable or disable each type of drop filter setting.
Note
You must use the policymgr interface <port-pair-name> re-configure command for the changes to take effect.
Enable the CLI configuration mode.
hostname > enable
hostname # configure terminal
Enable sending a TCP reset message for the relevant operational mode.
hostname (config) # policymgr interface <port-pair-name> drop tcp reset enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Enable sending a TCP reset message to the client for the relevant operational mode.
hostname (config) # policymgr interface <port-pair-name> drop tcp reset client enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Enable sending a TCP reset message to the server for the relevant operational mode.
hostname (config) # policymgr interface <port-pair-name> drop tcp reset server enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Enable sending an icmp-port-unreachable message to the sender for the relevant operational mode.
hostname (config) # policymgr interface <port-pair-name> drop udp icmpport-unreachable enablewhere
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Specify when a specific A or B monitoring interface is configured for out-of-band tap mode blocking with TCP reset, UDP, or HTTP-enabled.
To specify blocked packets that are sent on outbound traffic by the Network Security appliance to the ether1 management interface:
hostname (config) # policymgr interface <port-pair-name> drop out-interface ether1
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.To specify blocked packets that are sent on outbound traffic by the Network Security appliance to the ether2 management interface:
hostname (config) # policymgr interface <port-pair-name> drop out-interface ether2
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.
Enable posting an HTTP comfort page to the HTTP requester.
hostname (config) # policymgr interface <port-pair-name> drop http comfort-page enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Specify a comfort page message.
To specify an access-denied (response type 401) message:
hostname (config) # policymgr interface <port-pair-name> drop http comfort-page response-type access-denied [message <message>]
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface and<message>(optional) specifies the text of the message.To specify an access-forbidden (response type 403) message:
hostname (config) # policymgr interface <port-pair-name> drop http comfort-page response-type access-forbidden [message <message>]
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface and<message>(optional) specifies the text of the message.
Reapply the configuration to the specified interface.
hostname (config) # policymgr interface <port-pair-name> re-configure
where <port-pair-name> specifies the designation (A or B) that is configured on the appliance interface.
Verify the status of the drop filter configuration settings.
hostname (config) # show policymgr drop configuration Policy drop filter configuration: ... HTTP Comfort Page: Enabled : yes Type : access-denied Message : The page you are trying to access, http://%U, has a potential threat detected. TCP Reset : Enabled : yes to Server : yes to Client : yes UDP ICMP Port-Unreachable: Enabled : yes
Save your changes.
hostname (config) # write memory
Saving configuration file ... Done!
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Disable sending a TCP reset message for the relevant operational mode.
hostname (config) # no policymgr interface <port-pair-name> drop tcp reset enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Disable sending a TCP reset message to the client for the relevant operational mode.
hostname (config) # no policymgr interface <port-pair-name> drop tcp reset client enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Disable sending a TCP reset message to the server for the relevant operational mode.
hostname (config) # no policymgr interface <port-pair-name> drop tcp reset server enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Disable sending an icmp-port-unreachable message to the sender for the relevant operational mode.
hostname (config) # no policymgr interface <port-pair-name> drop udp icmpport-unreachable enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Disable posting an HTTP comfort page to the HTTP requester.
hostname (config) # no policymgr interface <port-pair-name> drop http comfort-page enable
where
<port-pair-name>specifies the designation (A or B) that is configured on the appliance interface.Verify the status of the drop filter configuration settings.
hostname (config) # show policymgr drop configuration Policy drop filter configuration: ... HTTP Comfort Page: Enabled : no Type : access-denied Message : The page you are trying to access, http://%U, has a potential threat detected. TCP Reset : Enabled : no to Server : no to Client : no UDP ICMP Port-Unreachable: Enabled : no
Save your changes.
hostname (config) # write memory
Saving configuration file ... Done!